Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

463 results about "Fuzz testing" patented technology

Fuzzing or fuzz testing is an automated software testing technique that involves providing invalid, unexpected, or random data as inputs to a computer program. The program is then monitored for exceptions such as crashes, failing built-in code assertions, or potential memory leaks. Typically, fuzzers are used to test programs that take structured inputs. This structure is specified, e.g., in a file format or protocol and distinguishes valid from invalid input. An effective fuzzer generates semi-valid inputs that are "valid enough" in that they are not directly rejected by the parser, but do create unexpected behaviors deeper in the program and are "invalid enough" to expose corner cases that have not been properly dealt with.

CAPEC vulnerability management system based on large language model

The invention discloses a CAPEC vulnerability management system based on a large language model, and belongs to the technical field of network security. The system comprises three modules: a vulnerability-CAPEC dynamic mapping module jointly encodes vulnerability description and code context through a bimodal large language model, accurately associates vulnerability logic with a CAPEC attack mode in combination with comparative learning and knowledge graph construction, and breaks through semantic limitation of traditional rule matching; the adversarial repair code generation module is used for generating high-robustness repair codes through adversarial training and syntax tree verification by fusing CAPEC relieving suggestions and code features on the basis of the association result, so that the secondary vulnerability risk is remarkably reduced; and the full-process automatic verification and DevOps integration module performs multi-dimensional security verification such as symbolic execution, fuzzy testing and the like on the generated repair code, and deeply integrates a development tool chain to realize real-time pushing and closed-loop management of a repair scheme.
Owner:BEIJING SHIXING TECH CO LTD

Fuzzy testing method, device and equipment based on large language model

The invention relates to a fuzzy testing method, device and equipment based on a large language model, and the method comprises the steps: analyzing and analyzing RFC standard documents of various network protocols through the large language model, and extracting protocol rules and constraint conditions; according to the protocol rule and the constraint condition, a large language model driving method is adopted to generate a test case conforming to protocol characteristics; and performing a differential test through the test case, and verifying the consistency between the actual software of the network protocol and the RFC standard document. According to the invention, the accuracy and security of implementation of the complex network protocol can be improved, and the test efficiency and coverage rate are optimized.
Owner:TIANJIN UNIV

Automatic feedback method based on protocol fuzz test and related equipment

The invention provides an automatic feedback method based on a protocol fuzz test and related equipment. The method comprises the following steps: acquiring a dynamic configuration file of the protocol fuzz test; performing real-time monitoring on the protocol fuzz test according to the protocol characteristic parameters of the dynamic configuration file, and determining a real-time data stream of the protocol fuzz test; performing multi-level feature analysis on the real-time data stream to judge an abnormal event existing in the protocol fuzz test; generating a feedback instruction corresponding to the abnormal event by performing multi-dimensional correlation analysis based on a knowledge graph on the abnormal event; and sending an exception notification mail to the user terminal according to the feedback instruction. Through an automatic mail notification mechanism, it is ensured that a tester can receive a notification immediately when a test task fails, the workload of manual monitoring is reduced, and the test efficiency is improved.
Owner:SECZONE TECH CO LTD

Fuzzy test Kubernete-based three-party component vulnerability mining method

The invention relates to a fuzzy test Kubernete-based three-party component vulnerability mining method, which comprises the following steps of: firstly, automatically identifying a user controllable function by combining a large language model based on an official document, a configuration list and source code information of a three-party component, and constructing a keyword dictionary to assist in large-scale identification of a potential target function; then analyzing context information of the target function and an interaction relation of the target function in a Kubernetes cluster, constructing a front dependency library required by fuzzy testing, and automatically generating a fuzzy testing driving program; integrating a fuzzy test driving program with a three-party component source code, performing code instrumentation, pre-compiling and corpus optimization, generating test input according to a set variation strategy, dynamically monitoring a coverage rate and an abnormal behavior, and continuously optimizing a test corpus; and finally, based on the crash behavior of the fuzzy test record, analyzing a trigger path of the vulnerability, performing vulnerability verification in a local Kubernetes cluster environment, and finally generating a vulnerability analysis report.
Owner:HANGZHOU DIANZI UNIV

Fuzz testing method, electronic device, and computer readable storage medium

PCT designated stage expiredWO2025123822A1Software testing/debuggingEquipment under testDatabase
Embodiments of the present disclosure provide a fuzz testing method, an electronic device, and a computer readable storage medium. The fuzz testing method comprises: acquiring a data packet; generating a protocol rule tree model on the basis of the data packet; generating a test case on the basis of the protocol rule tree model; sending the test case to a device under test; and determining a test result on the basis of response information of the device under test.
Owner:ZTE CORP

Fuzzy test method and device, equipment, storage medium and product

The invention discloses a fuzzy testing method and device, equipment, a storage medium and a product, and the method comprises the steps: obtaining a target code, carrying out the static analysis of the target code, and determining the possible vulnerability information and vulnerability reachable path information of the target code; generating a test seed according to the possible vulnerability information and the vulnerability reachable path information; performing a fuzzy test on the target code through the test seed, determining vulnerabilities existing in the target code, and collecting dynamic feedback information in the fuzzy test process; and optimizing the test seed according to the dynamic feedback information, and returning to execute the step of performing the fuzzy test on the target code through the test seed until a preset test stop condition is met. According to the fuzzy test method disclosed by the invention, the dynamic feedback information is collected in each fuzzy test process, and the test seeds are optimized according to the dynamic feedback information, so that the test efficiency and accuracy can be improved, and finally efficient vulnerability detection and security evaluation are realized.
Owner:INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER +2

Network protocol fuzz testing method based on strategy gradient reinforcement learning

The invention provides a network protocol fuzz testing method based on strategy gradient reinforcement learning, and relates to the technical field of fuzz testing, and the method comprises the steps: building a test corpus through obtaining a to-be-tested protocol data packet format; establishing an action space containing a mutation operation set and a state space of a benchmark test data packet feature vector; determining a reward value based on the test result; calculating a strategy gradient by using a reward value, and updating strategy network parameters in combination with an adaptive learning rate; and performing fuzzy testing by using the trained model. According to the invention, the test efficiency is improved, the variation strategy selection is optimized, and the effectiveness of the network protocol security test is enhanced.
Owner:ZHEJIANG SHUXIN NETWORK CO LTD

Virtual Computer Model-Based Fuzz Testing System and Method

The present invention provides a fuzz testing system and method based on a virtual computer model. Traditional fuzz testing approaches primarily modify external inputs to detect security vulnerabilities, making it difficult to monitor internal state changes in real-time. This invention constructs a test environment using a virtual computer model and incorporates automatic assertion generation and detection functions, enabling precise analysis of both internal and external signals of the system. After executing fuzz testing, assertion data is analyzed to assess test coverage and identify untested code regions, allowing for an optimized testing strategy. This improves the detection rate of security vulnerabilities, enhances test automation and reliability, and can be applied in various fields such as networks, automotive ECUs, IoT, finance, aerospace, and semiconductors.
Owner:AXION CO LTD

Industrial control protocol intelligent fuzzy test method and system based on multi-agent large model

The invention discloses an industrial control protocol intelligent fuzzy test method and system based on a multi-agent large model, and relates to an industrial information security test method and system.According to the industrial control protocol intelligent fuzzy test method and system based on the multi-agent large model, the large model is enhanced by integrating the field of the retrieval enhancement generation (RAG) and the low-rank quantization adaptation (QLoRA) technology, and a multi-agent cooperation mechanism is combined; and full-automatic, high-precision and end-to-end fuzzy testing of the industrial protocol is realized. The system generates seed data meeting protocol specifications through the seed generation agent, the test case generation agent executes field, structure and semantic variation based on the seed data, efficient test cases are dynamically generated, a test strategy is optimized in real time through the feedback analysis and strategy adjustment agent, and the vulnerability discovery capability is improved. By dynamically adjusting the variation strategy and optimizing the generation of the test case, the coverage, the accuracy and the efficiency of the test are improved, and the security and the vulnerability detection capability of the industrial control system are remarkably improved.
Owner:SHENYANG INSTITUTE OF CHEMICAL TECHNOLOGY

Knowledge extraction and envelope coverage-oriented software vulnerability test method and related equipment

The invention discloses a knowledge extraction and envelope coverage-oriented software vulnerability test method and related equipment, and the method comprises the steps: obtaining vulnerability key information of target software, and obtaining sensitive function features through defect dependence analysis and construction based on the vulnerability key information; performing semantic analysis on the analysis report and the code abstract associated with the sensitive function characteristics, screening to obtain a target sensitive function, performing path envelope reverse tracking on the target sensitive function, and constructing to obtain a target path envelope; and obtaining coverage information enveloped by the target path, and carrying out fuzzy testing on the basis of the coverage information in combination with the iteratively optimized variation sample. According to the method, through intelligent closed loop of analysis-positioning-testing-feedback-optimization, static analysis provides accurate guidance for dynamic testing, and the static analysis strategy is inversely optimized by the result of the dynamic testing, so that the maximum improvement of the testing efficiency and the vulnerability discovery accuracy is realized in limited testing resources, and the testing efficiency and the vulnerability discovery accuracy are improved. The method can be widely applied to the technical field of software security.
Owner:GUANGZHOU UNIVERSITY

An Optimization Method for Industrial Control Protocol Fuzz Testing Based on Coverage Guidance

The present invention discloses an optimization method for industrial control protocol fuzz testing based on coverage guidance. This method combines mutation testing on the basis of traditional coverage-guided fuzz testing. By comparing the output results of the program under test and the mutated PUT, high-quality test cases are screened. At the same time, the concept of coverage-guided tracking is introduced. By encoding the current coverage boundary in the binary file of the program under test, self-reporting can be performed when new coverage is generated in the test case, eliminating unnecessary tracking of the coverage-guided fuzzer, improving the fuzz testing efficiency, and greatly enhancing the vulnerability detection ability and testing efficiency of coverage-guided fuzz testing.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Stateful protocol fuzzy test method and system based on large model construction state machine

The invention discloses a stateful protocol fuzz testing method and system based on a large model construction state machine, and the method comprises the steps: firstly preprocessing a protocol specification document, guiding an information large model to analyze through cue words to obtain state machine information, constructing an initial state machine through the state machine large model, and initializing a message dictionary; secondly, protocol testing is carried out based on an initial state machine, a prompt word is input into a large testing model to understand a flow log, a message field supplement and improvement dictionary is obtained, message request fields and response codes in the message dictionary are combined, the initial state machine is improved, and a fine-grained state machine is obtained; and finally, on the basis of a fine-grained state machine, inputting cue words, analyzing a blind area covered by the current test by an analysis large model, and guiding a fuzzy tester to preferentially test an uncovered state which is most likely to trigger the deep vulnerability, thereby completing the fuzzy test. According to the method, the fuzzy device directionally tests the potential test state area, and accurate and efficient fuzzy testing is carried out.
Owner:HANGZHOU DIANZI UNIV +2

Software supply chain vulnerability verification code generation method based on guide fuzzy testing

The invention discloses a software supply chain vulnerability verification code generation method based on guiding fuzzy testing. The method comprises the steps that s1, a tripartite library dependency graph with a binary program as a starting node is generated; s2, performing static component analysis on the target application software component to form a component dependency graph; analyzing the component dependency graph layer by layer, and constructing an overall function call graph; s3, matching all vulnerability functions existing in the three-party component based on CVE information, calculating vulnerability function layer distance according to an overall function call graph, and performing directed utility calculation on a prepositioned function and a function priority for fuzzy test energy distribution; s4, performing key node identification and vulnerability distance calculation on a tripartite library critical function in the overall function call graph; and s5: transmitting binary static analysis results of s1 to s4 to a fuzzy test tool for directional fuzzy test. The method has the advantages of being simple in principle, easy to implement, higher in testing capacity, better in applicability and the like.
Owner:NAT UNIV OF DEFENSE TECH

GUI (Graphical User Interface) program fuzzing test method and system, computer equipment and storage medium

The invention discloses a GUI (Graphical User Interface) program fuzz test method and system, computer equipment and a storage medium, and the method comprises the steps: firstly designing a hyper-call interface of a KVM (Keyboard Virtual Machine), and then designing a QEMU (Query Empirical Mode Unit) monitor for responding to a call number and a corresponding function code of the hyper-call interface of the KVM; the method comprises the following steps: writing a code library in which a call number and a corresponding function code are packaged for external call, injecting the code library into a target GUI program, creating a Windows agent layer under a Windows system, finishing a fuzzy test on the target GUI program through the Windows agent layer, creating a Linux agent layer under a Linux system, and finishing a fuzzy test on the target GUI program through the Linux agent layer. According to the method, the fuzzy test range of the GUI program can be expanded, and the fuzzy test speed of the GUI program is increased.
Owner:HUNAN FANLIAN XINAN INFORMATION TECH CO LTD

Database fuzzy testing method and system based on depth feedback and semantic preservation

The invention relates to the technical field of computer software security, and provides a database fuzz testing method and system based on depth feedback and semantic preservation, and the method comprises the steps: collecting a standard query template, setting a variation rule base, and generating a variation strategy through a variation strategy generator; sending the variation strategy to a target database for fuzzy testing, and recording response information of the target database to the variation strategy; response information is obtained in real time through a depth feedback mechanism, and a variation strategy is dynamically optimized; generating a test case through a semantic preserving strategy; the priority of the test tasks is dynamically adjusted through an intelligent scheduling module, and resource allocation is carried out; and executing the test case to obtain a test result. According to the method, the effectiveness and the reliability of database fuzzy testing are remarkably improved, the capability of discovering deep security vulnerabilities is greatly enhanced, and powerful support is provided for protecting the database from being threatened by various unknown attack modes.
Owner:TIANJIN NANKAI UNIV GENERAL DATA TECH

Protocol security fuzz test system and test method based on speed reduction bridge

The invention provides a protocol security fuzzy test system and method based on a speed reduction bridge, the speed reduction bridge is integrated on an FPGA board card, and the speed reduction bridge comprises a protocol fuzzy test processing module, a clock domain crossing buffer and flow control module and a programmable time sequence fault injection circuit. The protocol-based fuzzy test processing module is used for detecting feature information and state information of a data stream flowing through the speed reduction bridge and outputting an action instruction; and based on different action instruction types, driving different modules to inject different types of abnormities into the data stream, and realizing fuzzy testing based on the abnormal data stream. The fuzzy test processing module is embedded in the FPGA logic, different rules can be matched according to the feature information of the data flow, different abnormal injection of the data flow is achieved, the abnormal injection opportunity is determined according to the link state information, the speed reduction bridge has the dual functions of normal protocol relaying and active abnormal injection at the same time, and the reliability of the speed reduction bridge is improved. The test of various abnormities of the equipment to be tested can be realized.
Owner:WUHAN LINGJIU MICROELECTRONICS CO LTD

Program fuzzing test method, system and equipment

The invention relates to a program fuzz testing method. The method comprises the following steps: acquiring a current variation execution option group and a current variation seed; wherein the execution option represents setting of the tested program, and the seed represents input data of the tested program; modifying a preset execution option group of the tested program into the current variation execution option group to obtain a program after the execution options are modified; inputting the current variation seed into the program after the execution option is modified, and executing the program after the execution option is modified to obtain an execution result; and if the execution result is abnormal, determining the program vulnerability according to the current variation execution option group and the current variation seed. The method can improve the vulnerability mining effect, and is applied to the technical field of network security.
Owner:TSINGHUA SHENZHEN INTERNATIONAL GRADUATE SCHOOL

Protocol fuzz testing method and system based on potential relationship between states

The invention belongs to the technical field of network security protocol vulnerability mining, and discloses a protocol fuzz testing method and system based on a potential relationship between states, the method comprises the following steps: in a state modeling stage, tracking directed edges in a tested program state machine to generate a state bitmap, the state bitmap comprising state transition information; in the state selection stage, a state selection problem is modeled as a multi-arm machine optimization problem, and the optimization problem is solved by using an Epsilone-Greedy algorithm and a Thompson sampling algorithm in combination with state transition information. According to the method, the state bitmap is designed to represent the condition of inter-state migration, basic state information is reserved, meanwhile, representation of the state machine is simplified, the mapping relation between the tested protocol state machine and the state bitmap is established, inter-state migration is abstracted into state points in the state bitmap, and therefore the process of constructing and analyzing the tested protocol state machine is simplified.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

MQTT protocol fuzz testing method and system based on large language model guidance sequence generative adversarial network

The invention discloses an MQTT protocol fuzzy testing method and system based on a large language model guiding sequence generative adversarial network, relates to the field of fuzzy testing, effectively combines the advantages of the large language model and the sequence generative adversarial network, and analyzes basic training data by introducing an intelligent analysis technology of the large language model. And the quality of the training sample of the sequence generative adversarial network is obviously improved. According to the method, the initial seeds can be enriched through the large language model, the discriminator can be assisted to perform multi-dimensional evaluation on the data generated by the generator, and the authenticity and diversity of the test seeds are enhanced. The generation of redundant test cases is greatly reduced, so that the fuzzy test process is more efficient. Meanwhile, a seed elimination technology based on an energy value is designed, it is further ensured that the tested seeds have higher quality, and the efficiency of vulnerability discovery is effectively improved. Meanwhile, according to the maximum coverage length, the test strategy is dynamically adjusted, continuous optimization of the test process is achieved, and a solid guarantee is provided for the test. According to the method, multi-level variation is carried out on the test seeds by utilizing a large language model, vulnerability information existing in the test seeds is quickly positioned, and meanwhile, multi-dimensional and deeper mutation is carried out on the test seeds, so that more existing vulnerability information is explored, namely, the multi-level mutation is carried out on the test seeds; the test seeds which successfully cause the vulnerabilities are verified and optimized by means of the response of the test target, the success and failure positions are summarized, and a more reliable guarantee is provided for subsequent variation.
Owner:LANZHOU UNIVERSITY OF TECHNOLOGY

A method, device and equipment for fuzz testing of operating system kernel

The present invention provides an operating system kernel fuzz testing method, device and equipment, which relate to the field of kernel fuzz testing technology. By obtaining the initial input and splitting the initial input to generate an input set; performing fuzz testing on the input set and obtaining the fuzz testing results; storing the fuzz testing results in a key component inference file to generate a key component inference table; generating a seed selection strategy in the seed library in combination with the key component inference table to guide seed mutation selection. By identifying and utilizing the key components in the system call sequence, the coverage of the fuzz test is improved. A correspondence between the key components in the system call sequence and the corresponding path basic blocks is established to better explore potential security vulnerabilities. According to the selection of mutation points, different mutation strategies are executed to effectively improve the existing fuzz testing method and improve the efficiency and quality of vulnerability mining.
Owner:NAT UNIV OF DEFENSE TECH

Seed scheduling method and system for multi-objective optimization in grey box fuzzy test

The invention relates to the technical field of program testing, in particular to a seed scheduling method and system for multi-objective optimization in grey box fuzzy testing, and the method comprises the steps: dividing related indexes of seeds into state related indexes and state independent indexes; modeling a priority ranking problem of the seeds into a multi-objective optimization problem according to state related indexes, calculating Pareto leading edges of the seeds based on a non-dominated ranking algorithm, and screening out the seeds with high priorities; selecting seeds according to a seed selection basic principle; determining the weight of each index by using an analytic hierarchy process according to the state-independent indexes, evaluating the quality of the seeds through an approximate ideal solution algorithm, and distributing reasonable energy for the seeds; and based on the priority and the energy distribution result, selecting the seeds for mutation to generate a new test case. According to the method, seed priority division and energy distribution are optimized, so that the seed scheduling efficiency in grey-box fuzzy testing is remarkably improved, and accurate testing is realized at a higher code coverage rate and a faster vulnerability discovery speed.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Fuzz testing of machine learning models to detect malicious activity on a computer

An example method can include, obtaining information about a machine learning (ML) model configured to detect malicious activity on a computer system, wherein the information includes one or more of a model type of the ML model, an output type of the ML model, or a type of malicious activity that the model is trained to detect, receiving a training dataset, wherein the training dataset includes a plurality of unlabeled examples, generating an additional dataset based on the training dataset using a generative model, wherein the additional dataset includes a plurality of additional unlabeled examples, and, training the machine learning model to generate labels for each example in the training dataset and the additional dataset, using a combination of the training dataset and the additional dataset, wherein the training includes adjusting one or more parameters of the machine learning model based on accuracy of the generated labels.
Owner:SOPHOS LTD

Fuzzy test verification method and system for password service interface

The invention discloses a fuzzy test verification method and system for a password service interface, and belongs to the technical field of password service technologies and software testing. The method comprises the following steps: firstly, constructing a password service interface feature library, and extracting key feature information; designing a multi-dimensional fuzzy test variation strategy based on the password service interface feature library, and generating a fuzzy test case set covering grammar exception, semantic exception and encryption scene exception; realizing communication adaptation between a test case and a target password service interface through a dynamic adaptation module, executing a fuzzy test, and collecting information such as response data and an operation state of the interface in real time; and finally, carrying out deep analysis on the acquired information through an anomaly detection and analysis module, positioning a vulnerability type and a trigger path, and generating a standardized test report. According to the method, different types of password service interfaces can be accurately adapted, the test coverage and the vulnerability discovery efficiency are remarkably improved, and reliable support is provided for security verification of the password service interfaces.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Deep learning framework fuzzy testing method based on large model cue word optimization

The invention relates to the cross technical field of artificial intelligence and software security testing, in particular to a deep learning framework fuzz testing method based on large model cue word optimization, which is used for improving vulnerability mining efficiency and testing intelligence level of fuzz testing on a deep learning framework. According to the method, the advantages of a large language model in the aspects of code understanding and generation are fully utilized, and efficient vulnerability detection of a deep learning framework is realized by introducing a cue word adaptive optimization and variation mechanism. The method mainly comprises the following steps: (1) providing a deep learning framework API classification method and a cue word routing mechanism; (2) proposing a large model cue word adaptive optimization mechanism; and (3) proposing a deep learning framework fuzzy test variation strategy and a dynamic selection mechanism. According to the method, the automation and vulnerability discovery capability of fuzzy testing can be remarkably improved while the generation quality is ensured, and the method has relatively high universality and application value.
Owner:HUNAN UNIV

Static binary code taint analysis method based on propagation action range

The invention discloses a static binary code taint analysis method based on a propagation action scope, and relates to the field of static binary code taint analysis, and the static binary code taint analysis method comprises the following steps: extracting a program instruction set and a control flow structure based on a disassembling result of a target binary code; calculating a value set with a source of the binary code based on the control flow graph; on the basis of the control flow diagram and the value set with the source, executing cross-function stain propagation analysis, and identifying memory positions or registers influenced by pollution in each function and propagation action ranges of the memory positions or the registers; and extracting all instruction sets using the taint data based on the taint and the propagation action range thereof. According to the method, the false alarm rate of static binary taint analysis can be reduced and the instruction set involved in the taint analysis can be reduced without increasing the analysis overhead, so that the method has important significance in improving the instrumentation efficiency and the operation efficiency of dynamic taint analysis and improving the accuracy of protocol reversion, fuzzy testing and vulnerability mining based on the taint analysis.
Owner:EAST CHINA NORMAL UNIV

Linux operating system drive fuzzy test system based on kernel device model

The invention provides an improved scheme of a fuzzy testing system of a Linux operating system. According to the scheme, fuzzy testing is guided by integrating device attributes, driving attributes and topological relations among devices. Specifically, a new syzlang description is generated by deeply analyzing a Linux kernel source code, so that a test case can introduce modification operation of equipment and drive attributes. Meanwhile, according to the scheme, the depth and the breadth of the fuzzy test are improved based on the corresponding relation between the equipment attribute file and the equipment file, so that the behavior of the kernel driver is more effectively explored. In addition, according to the scheme, concurrent testing is guided through the topological relation between the devices, testing cases related to device attributes and drive attributes are increased, the testing efficiency is further improved, the coverage rate of fuzzy testing is increased, and finally the testing process can reveal vulnerabilities caused by memory errors of a kernel of the Linux operating system in different states.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Concurrent vulnerability fuzzy test method and device supporting reproduction

The invention provides a concurrent vulnerability fuzzy test method and device supporting reproduction, and relates to the technical field of computers, the method comprises the following steps: obtaining a target program obtained by rewriting an original binary program; wherein the target program comprises a plurality of key basic blocks, and the execution sequence of the key basic blocks is used as a thread interleaving feedback signal; performing thread staggering variation based on the key basic block to generate a plurality of target test cases containing a plurality of thread staggering conditions; performing a fuzzy test based on the plurality of target test cases, and reproducing a crash scene based on execution information of the target program under the condition that the target program is triggered to crash in the fuzzy test process; wherein the execution information is obtained by recording the execution sequence of the key basic blocks in the execution process of the target program. Through the method provided by the invention, concurrent vulnerabilities can be effectively mined, and recurrent fuzz testing can be carried out.
Owner:TSINGHUA UNIVERSITY +1

Intelligent fuzzy testing method and device based on large language model and medium

The embodiment of the invention discloses an intelligent fuzzy testing method and device based on a large language model and a medium, and relates to the technical field of fuzzy testing, and the method comprises the steps: obtaining and analyzing a source code of a target code library to construct a structured knowledge graph, and evaluating a function vulnerability risk through the large language model and the structured knowledge graph, generating a test target sorting list; performing multi-dimensional code analysis on the selected test targets in the test target sorting list to generate seed input so as to construct a compilable test driver through the seed input; performing a test driver in an isolated environment, performing a fuzz test using a seed input, collecting a crash report to analyze the crash report, identify a crash cause, and generate a minimization replicator; and generating a candidate patch based on the crash reason, and verifying the validity of the candidate patch through a minimization reproducing device and a structured knowledge graph so as to realize the fuzzy test of the source code of the target code library.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Method for testing device software of a device by means of a fuzzing algorithm

A method for testing device software of a device using a fuzzing algorithm. The method includes: initializing the fuzzing algorithm to detect an initial behavior of the device software of the device under test; executing a fuzzing test loop including: generating a fuzzed message from predefined message types; sending the generated, fuzzed message to the device under test to test the device software on the basis of the fuzzed message; detecting side-channel information during testing of the device software on the basis of the fuzzed message; recognizing anomalies in the side-channel information using at least one machine learning model and / or statistical algorithm; and if an anomaly is recognized, adjusting a parameter including adjusting fuzzability weights, of the initialized fuzzing algorithm and performing a next loop iteration of the fuzzing test loop; and if no anomaly is recognized, performing the next loop iteration of the fuzzing test loop.
Owner:ROBERT BOSCH GMBH

Fuzzy test method and system based on program control flow

The invention relates to the technical field of industrial automation control system testing, and particularly discloses a fuzzy testing method and system based on program control flow, and the method comprises the steps: obtaining parameter data; analyzing the process parameter data and the environment disturbance data to obtain a mutation point; eliminating the process parameter data mutated due to interference of the environmental disturbance data according to the mutational points to obtain target process parameter data; extracting environment disturbance data, execution path data and production quality data in the event window; generating triple data; performing clustering analysis on the triple data in the same event window, and determining an abnormal cluster and a corresponding abnormal type; and according to the abnormal triple data, constructing a fuzzy test case. According to the method, parameter fluctuation under a normal working condition is prevented from being misjudged as system abnormity, internal defects and external interference factors of the system are effectively distinguished, and accurate filtering of external environment interference is realized.
Owner:PLA PEOPLES LIBERATION ARMY OF CHINA STRATEGIC SUPPORT FORCE AEROSPACE ENG UNIV